The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,222 vulnerabilities with CWE-862
CVE-2026-1942
MEDIUM
Blog2Social <= 8.7.4 - Authenticated Arbitrary Post Modification
CVSS 6.5
CVE-2026-2127
MEDIUM
SiteOrigin Widgets Bundle <=1.70.4 - Auth Bypass
CVSS 5.4
CVE-2026-1656
MEDIUM
WordPress Business Directory Plugin <=6.4.20 - Auth Bypass
CVSS 5.3
CVE-2026-1938
MEDIUM
YayMail WooCommerce Email Customizer <=4.3.2 - Auth Bypass
CVSS 5.3
CVE-2026-1860
MEDIUM
Kali Forms <2.4.8 - Insecure Direct Object Reference
CVSS 4.3
CVE-2026-1831
LOW
YayMail WooCommerce Email Customizer <=4.3.2 - Privilege Escalation
CVSS 2.7
CVE-2026-1655
MEDIUM
EventPrime WordPress Plugin <=4.2.8.4 - Privilege Escalation
CVSS 4.3
CVE-2026-2633
MEDIUM
Gutenberg Blocks with AI by Kadence WP - Privilege Escalation
CVSS 4.3
CVE-2026-1937
HIGH
YayMail WooCommerce Email Customizer <=4.3.2 - Privilege Escalation
CVSS 7.2
CVE-2026-1640
MEDIUM
Taskbuilder WordPress Plugin <5.0.2 - Auth Bypass
CVSS 4.3
CVE-2026-1906
MEDIUM
PDF Invoices & Packing Slips for WooCommerce <=5.6.0 - Insecure Dir...
CVSS 4.3
CVE-2026-1925
MEDIUM
EmailKit for WordPress <=1.6.2 - Auth Bypass
CVSS 4.3
CVE-2026-2608
MEDIUM
Kadence Blocks <=3.5.32 - Auth Bypass
CVSS 4.3
CVE-2026-25903
MEDIUM
Apache NiFi 1.1.0-2.7.2 - Privilege Escalation
CVSS 6.6
CVE-2026-0829
MEDIUM
Frontend File Manager Plugin 23.5 - Info Disclosure
CVSS 5.8
CVE-2026-1657
MEDIUM
EventPrime WordPress Plugin <4.2.8.4 - Unauthenticated File Upload
CVSS 5.3
CVE-2026-2001
HIGH
WowRevenue WordPress Plugin <=2.1.3 - Authenticated RCE
CVSS 8.8
CVE-2026-0998
MEDIUM
Mattermost 11.1.x-11.1.2 - Auth Bypass
CVSS 4.3
CVE-2026-0929
MEDIUM
RegistrationMagic <6.0.7.2 - Privilege Escalation
CVSS 4.3
CVE-2026-26368
HIGH
eNet SMART HOME 2.2.1/2.3.1 - Privilege Escalation
CVSS 8.8
CVE-2026-26367
HIGH
eNet SMART HOME 2.2.1/2.3.1 - Privilege Escalation
CVSS 8.1
CVE-2026-2312
MEDIUM
Media Library Folders <8.3.6 - Privilege Escalation
CVSS 4.3
CVE-2026-1254
MEDIUM
Modula Image Gallery - Photo Grid & Video Gallery <2.13.6 - Auth By...
CVSS 4.3
CVE-2026-2022
MEDIUM
WordPress Smart Forms <2.6.99 - Info Disclosure
CVSS 4.3
CVE-2026-1944
MEDIUM
CallbackKiller service widget <1.2 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
8,222
Exploit Likelihood
High